



Do you want to show that your organization works with modern IT systems and smart data management?
Do you want to show that your organization works with modern IT systems and smart data management?
ISO 27001 certification
Reliable information security with ISO 27001
Outdated technology, misusing IT or malware infections. These can all lead to cybercrime, IT failures, espionage and data misuse. How should you implement a strong information security strategy? ISO 27001 certification gives you this opportunity, letting you protect confidential information in your organization. DEKRA is happy to test your organization against the international ISO/IEC 27001 standards.
Benefits of ISO IEC 27001 certification
- protection of confidential data and information
- identification and reduction of threats to your organization
- protection of the trust of clients and business partners
- strengthening of competitiveness
The ISO 27001 certification process
Phase 1
2. Determine the information security objectives.
3. Develop a methodology for risk assessment and risk treatment.
4. Establish a statement of applicability (SoA).
5. Draw up a risk management plan and risk assessment report.
6. Establish security roles and responsibilities.
7. Draw up a resource list for technical measures.
8. Ensure acceptable use of resources.
9. Establish guidelines, for example for access control in accordance with Annex A of ISO 27001.
Phase 2
People Based Auditing (PBA)
New version ISO 27001 2022
- The standard is structured according to the Harmonized Structure
- Annex A of the standard is divided into 4 chapters (according to ISO/IEC 27002:2022):
- A. organizational measures
- B. personnel measures
- C. physical measures
- D. technological measures
NEN-EN-ISO/IEC 27001:2023

Book a free session with our expert
Q&A: ISO 27001 in brief
2. In phase 2 we audit the implementation. For example, we consider the effective operation of the management system.
3. If our assessment is positive, you receive the certificate.
4. We conduct follow-up audits annually.
5. A recertification follows after three years.

CSR Performance Ladder with 33 indicators

NEN 7510: Information security in Dutch healthcare

Internal audit

Environmental management system and ISO 14001

What is a CCV pentest?

Risk analysis in information security

Difference between ISO 27001 and NEN 7510

ISO 27001 information security policy
